Selects and Premiere Assistant Are Now Backed by SOC 2 Type II Compliance
Cutback has completed a SOC 2 Type II audit covering the infrastructure behind Selects and Premiere Assistant. Here's what that means if you're evaluating either for enterprise use.

TLDR: Cutback holds SOC 2 Type II compliance, meaning both Selects and Premiere Assistant are built on independently audited security practices, not just documented policy.
If your team is evaluating Selects or Premiere Assistant for a production workflow, you're probably evaluating a specific tool that's going to touch your footage, your project files, and in a lot of cases, content that hasn't been released yet. For enterprise teams, content studios, and corporates handling either sensitive information for in-house corporate videos and training, or teams handling external marketing materials, security and privacy can be paramount to your decision-making when choosing the right SOC-compliant video editing software. This post will answer everything you need to know to make your decision.
Cutback has completed a SOC 2 Type II audit, verified against the AICPA's SOC framework.
Because SOC 2 compliance is assessed at the company and infrastructure level, it covers the systems, access controls, and organizational practices that both Selects and Premiere Assistant are built and operated on, not a separate certification per product, but the same audited foundation underneath both.
What is a SOC 2 Report?
A SOC 2 report is the output of an independent audit that evaluates how a company protects the data it handles. It's a formal, detailed report produced by an independent auditor, and it's the standard reference point enterprise security teams use when evaluating a new vendor.
SOC 2 audits are structured around a defined set of categories. For Cutback, the audit covers:
Infrastructure security: including restricted encryption key access, unique authentication requirements for every account, and access to production applications, databases, networks, and firewalls limited to authorized personnel with a documented business need.
Organizational security: including employee background checks, mandatory security awareness training, signed confidentiality agreements for employees and contractors, and an enforced code of conduct
Product security: including documented and annually tested business continuity and disaster recovery plans, a formal software development lifecycle, configuration management procedures, and board-level oversight of cybersecurity and privacy risk.
Data and privacy: including formal data retention and disposal procedures, and a data classification policy governing how confidential data is secured and restricted.
What is a SOC 2 Audit, and Why Does "Type II" Matter?
There are two types of SOC 2 (System and Organization Controls 2) audits, and the difference between them is the most important thing to know when evaluating a vendor's claim.
SOC 2 Type I
An SOC 2 Type I (or SOC 2 Type 1) audit checks whether the right controls exist, at one point in time. It confirms a company has the right policies on paper.
SOC 2 Type II
An SOC 2 Type II (or SOC 2 Type 2) audit, the one Cutback has completed, checks whether those controls were actually followed consistently over a real operating period. It's independent verification that the practices weren't just written down but observed in actual use. That's a meaningfully higher bar, and it's the version that carries real weight with enterprise security teams.
Is Selects Secure for Enterprise Use?
If you're bringing raw footage into Selects, unreleased campaign material, documentary footage under embargo, client-confidential recordings, the question isn't just, "Does it work?" It's, "What happens to that footage while it's in the system?"
SOC Type II compliance means the infrastructure Selects runs on has been independently audited against the control categories above: restricted production access, encrypted key management, monitored systems, and a tested disaster recovery plan. That's the same standard of scrutiny enterprise teams apply when evaluating any vendor handling sensitive files, including video footage.
Is Premiere Assistant Secure for Enterprise Use?
The same audited infrastructure and organizational controls apply to Premiere Assistant. Since Premiere Assistant operates as a plugin inside your existing Adobe Premiere environment, the relevant question for a security review is typically what happens on Cutback's side of that connection, how access is controlled, how data is retained, and how the company itself is organized to prevent and respond to incidents.
What This Means If You're Evaluating Enterprise Video Editing Tools
Whether you're bringing in Selects as a standalone pre-editing layer, Premiere Assistant as an in-timeline plugin, or using both together, the security review questions are largely the same: who can access production systems, how is data retained and disposed of, what happens if something goes wrong, and is any of this independently verified rather than self-reported? SOC 2 Type II compliance is built to answer exactly those questions with an audited answer rather than a verbal assurance.
Verify it Yourself
The full audit report and control details are available through the Cutback Trust Center, where enterprise teams can request direct access to the complete documentation as part of their own vendor review process.
If your team is evaluating Selects, Premiere Assistant, or both for a workflow involving sensitive or pre-release content, reach out to our team, and we'll gladly walk through our security practices directly.
Frequently Asked Questions (FAQs)
Q: Is Selects secure for enterprise use?
A: Selects operates on infrastructure covered by Cutback's SOC 2 Type II audit, which includes restricted production system access, encrypted key management, continuous vulnerability and system monitoring, and a tested disaster recovery plan. For teams handling unreleased or confidential footage, this means the security practices behind Selects have been independently verified, not self-reported.
Q: Is Premiere Assistant secure for enterprise use?
A: Yes, Premiere Assistant is built on the same audited infrastructure and organizational controls covered by Cutback's SOC 2 Type II compliance, including access controls, data retention and disposal procedures, and board-level oversight of cybersecurity risk.
Q: What is a SOC 2 audit?
A: A SOC 2 (System and Organization Controls 2) audit is an independent evaluation of a company's security controls against a defined set of categories, including infrastructure security, organizational security, product security, internal security procedures, and data privacy. The audit results in a formal report that vendors can share with prospective enterprise customers. This audit framework is by the American Institute of Certified Public Accountants (AICPA).
Q: What is the difference between SOC 2 Type I and SOC 2 Type II?
A: A Type I audit confirms that the right security controls exist at a single point in time. A Type II audit, which Cutback holds, confirms those same controls were actually followed consistently over a real operating period, independently observed rather than just documented. Type II is the more rigorous of the two.
Q: Where can I get Cutback's SOC 2 report?
A: The full audit report and control details are available through the Cutback Trust Center, where enterprise teams can request direct access as part of their own vendor security review.

Cutback Team
Share post






